Vulnerabilities
Vulnerable Software
Eq-3:  >> Ccu2 Firmware  >> 2.41.9  Security Vulnerabilities
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
CVSS Score
8.8
EPSS Score
0.078
Published
2019-10-17
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-10-17
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clear the system protocol or modify/delete internal programs, etc. pp.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-08-06
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a new user in the system, or modify/delete internal programs.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-08-05


Contact Us

Shodan ® - All rights reserved